« Volver al listado

Btcpayserver

Btcpayserver Btcpay Server: vulnerabilidades y CVE

Btcpayserver Btcpay Server tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses0
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-1149Media (5.4)0.55%—2 mar 2023
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.
CVE-2023-0879Media (5.4)0.48%—17 feb 2023
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
CVE-2022-32984Alta (7.5)1.0%—31 ene 2023
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the…
CVE-2023-0493Alta (8.8)7.9%—26 ene 2023
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
CVE-2021-3830Media (5.4)0.56%—26 sept 2021
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3646Media (6.1)0.77%—10 sept 2021
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-29250Media (5.4)0.53%—5 may 2021
BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing.
CVE-2021-29248Media (5.3)0.82%—5 may 2021
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.
CVE-2021-29247Media (5.3)1.2%—5 may 2021
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.
CVE-2021-29246Media (6.7)1.5%—5 may 2021
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload…
CVE-2021-29245Media (5.3)0.95%—5 may 2021
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
CVE-2021-29251Media (6.5)0.79%—1 abr 2021
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured.
CVE-2021-29249Alta (7.5)1.2%—26 mar 2021
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.

Otros productos de Btcpayserver